CVE-2026-108593
Deferred Deferred - Pending Action

Configuration Injection in 9router Dashboard

Vulnerability report for CVE-2026-108593, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

9router 0.4.1 through 0.5.99 contains a configuration injection vulnerability in the POST /api/cli-tools/hermes-settings endpoint that allows authenticated dashboard users to inject arbitrary keys into the Hermes Agent config.yaml file. Attackers can submit a baseUrl containing double quotes and newlines to add hooks_auto_accept and a hooks.post_llm_call shell command, which Hermes Agent executes without approval after an LLM call.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
decolua 9router 0.4.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a configuration injection flaw in 9router versions 0.4.1 through 0.5.99. It exists in the POST /api/cli-tools/hermes-settings endpoint where authenticated users can inject arbitrary keys into the Hermes Agent's config.yaml file by submitting a baseUrl containing double quotes and newlines. This allows adding malicious configurations like hooks_auto_accept and a hooks.post_llm_call shell command that executes arbitrary commands without approval after an LLM call.

Detection Guidance

Check the Hermes Agent config.yaml file (~/.hermes/config.yaml) for unexpected hooks_auto_accept or hooks.post_llm_call entries. Review 9router API logs for POST requests to /api/cli-tools/hermes-settings with baseUrl containing quotes or newlines. Inspect running Hermes Agent processes for unauthorized shell commands.

Impact Analysis

An attacker with access to the 9router dashboard can execute arbitrary shell commands on the system running Hermes Agent. This could lead to full system compromise, data theft, or further network infiltration. The attack requires authenticated access to the dashboard or a misconfigured deployment without login requirements.

Compliance Impact

This vulnerability could lead to unauthorized code execution, potentially violating data protection requirements under GDPR and HIPAA. It may result in unauthorized access to personal or health data, triggering compliance violations and legal consequences for organizations failing to secure their AI agent integrations.

Mitigation Strategies

Upgrade 9router to a patched version. Disable unauthenticated dashboard access if configured with requireLogin: false. Validate and sanitize all inputs to the baseUrl field in the /api/cli-tools/hermes-settings endpoint. Restrict Hermes Agent permissions to prevent unauthorized file modifications.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108593. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart